# Sobig aftereffects: email piling up?

**URL:** <https://boards.straightdope.com/t/sobig-aftereffects-email-piling-up/199355>\
**Category:** Factual Questions\
**Created:** [September 3, 2003, 5:18pm UTC](https://boards.straightdope.com/t/sobig-aftereffects-email-piling-up/199355 "2003-09-03T17:18:35Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Musicat](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/musicat/32/20189_2.png) [@Musicat](https://boards.straightdope.com/u/Musicat)\
**Post date:** [September 3, 2003, 5:18pm UTC](https://boards.straightdope.com/t/sobig-aftereffects-email-piling-up/199355/1 "2003-09-03T17:18:35Z")

</div>

Nearly a week ago, I noticed the volume of my non-virus email, spams included, had dropped off from the typical 60 messages a day to about 3.

I have no spam filter activated (I do have a virus filter in place, and it reported a drastic dropoff in Sobigs & Blasters, but that might be because the worldwide infection is running its course).

Tests of messages sent from me to me, even from a hotmail addr to my non-hotmail addr (and vice-versa) were delivered within minutes to hours, but a test sent from a friend’s mailbox showed only 1/2 of the mail is being delivered within 24 hours. The rest has not yet arrived.

Mail sent to one domain seems to get to me, but another domain that forwards mail to me does not. The Registrar of the latter domain says nothing is wrong on their end, and the account is paid up for several years.

My ISP claims their email servers, due to the Sobig/Blaster epidemic, have been spooling all messages, doing load balancing, etc., and I will eventually get everything that is being stored. But they cannot say if that will be hours, days, or weeks. Meanwhile, I am in limbo, and don’t know if people can communicate with me or not. Outgoing mail seems to work, but I can’t be sure about that, either.

Anyone else experiencing this kind of email bottleneck or delays? Or is the ISP just stringing me along with an excuse for a failure on their part?

---

<div class="post-metadata">

**Author:** ![John\_Zahn](https://avatars.discourse-cdn.com/v4/letter/j/e0b2c6/32.png) [@John\_Zahn](https://boards.straightdope.com/u/John_Zahn)\
**Post date:** [September 3, 2003, 6:12pm UTC](https://boards.straightdope.com/t/sobig-aftereffects-email-piling-up/199355/2 "2003-09-03T18:12:45Z")

</div>

Some ISP’s are better than others about keeping the after effects of all of that stuff out. I think AOL does a pretty good job here. Mine isn’t so good. I’m getting about 3-10 e-mails a day too, which mostly seem to be the after effects of this particular virus. I talked to my computer guru about this a week earlier, and he said as long as I’m not opening the attachments, and not clicking on to other stuff, I probably won’t get infected. So even if you’re getting messages claiming to have been sent to you, or claiming your computer is infected, it’s a good chance it’s not. I’ve done the virus scans and mine continue to check out okay. There is one virus among a few others along the lines of KLEZ that will automatically infect your computer, simply by just getting into your mail once you’ve only highlighted it in blue once. I had one of those before I got Norton anti-virus. These are mostly variations of the older KLEZ, and any good virus protection program should automatically be taking care of these for you.

JZ

---

<div class="post-metadata">

**Author:** ![Musicat](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/musicat/32/20189_2.png) [@Musicat](https://boards.straightdope.com/u/Musicat)\
**Post date:** [September 3, 2003, 8:04pm UTC](https://boards.straightdope.com/t/sobig-aftereffects-email-piling-up/199355/3 "2003-09-03T20:04:49Z")

</div>

**John Zahn,** I don’t have a virus. This is not about an infection in my computer(s), and I am well aware of the characteristics of the common strains like Klez, Sobig, Badtrans, etc. (until the number of worms reached 50 per hour recently, I enjoyed sorting them out manually and didn’t use an automatic filter).

I am talking about receiving email and a possible backlog of messages, legitimate & otherwise, that may be waiting in a queue somewhere to be spewed out to my mailbox eventually. Any involvement with a virus may be only the extreme traffic that the Sobig & Blaster generated a few weeks ago, clogging the Internet pipeline.

---

<div class="post-metadata">

**Author:** ![sailor](https://avatars.discourse-cdn.com/v4/letter/s/a587f6/32.png) [@sailor](https://boards.straightdope.com/u/sailor)\
**Post date:** [September 3, 2003, 9:37pm UTC](https://boards.straightdope.com/t/sobig-aftereffects-email-piling-up/199355/4 "2003-09-03T21:37:59Z")

</div>

I have noticed a _very_ sharp drop in spam at hotmail but have received my emails pretty normally. I believe they are just getting more effective at blocking spam, not that everything is being delayed.

---

<div class="post-metadata">

**Author:** ![Musicat](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/musicat/32/20189_2.png) [@Musicat](https://boards.straightdope.com/u/Musicat)\
**Post date:** [September 3, 2003, 11:09pm UTC](https://boards.straightdope.com/t/sobig-aftereffects-email-piling-up/199355/5 "2003-09-03T23:09:09Z")

</div>

But I have no spam blocker active at my computer or at my ISP. My ISP offers Postini, but the spam function is turned off.

---

<div class="post-metadata">

**Author:** ![AskNott](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/asknott/32/5790_2.png) [@AskNott](https://boards.straightdope.com/u/AskNott)\
**Post date:** [September 4, 2003, 2:25am UTC](https://boards.straightdope.com/t/sobig-aftereffects-email-piling-up/199355/6 "2003-09-04T02:25:49Z")

</div>

I haven’t gotten any e-mail since Aug. 28th. My ISP, insight, is blaming it on my McAfee SpamKiller. I’ve been trying to tweak past it without paying a passel of tech-support charges, without success so far. I’ve been getting angry over it, and I don’t like getting angry.

---

<div class="post-metadata">

**Author:** ![Musicat](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/musicat/32/20189_2.png) [@Musicat](https://boards.straightdope.com/u/Musicat)\
**Post date:** [September 4, 2003, 2:29am UTC](https://boards.straightdope.com/t/sobig-aftereffects-email-piling-up/199355/7 "2003-09-04T02:29:01Z")

</div>

My mail is definitely not getting thru – I’d say 85% is getting returned, blocked or delayed for days. Here is part of the error message received by a friend who tried to send me something:

* * *

----- Original Message -----  
From: \<[MAILER-DAEMON@remt21.cluster1.charter.net](mailto:MAILER-DAEMON@remt21.cluster1.charter.net)\>  
To: \<[mzpat@charter.net](mailto:mzpat@charter.net)\>  
Sent: Tuesday, September 02, 2003 7:00 PM  
Subject: Undeliverable mail: none

## Failed to deliver to ‘musicat@doorbell.net’ SMTP module(domain [doorbell.net](http://doorbell.net)) reports: [eforward1.enom.com](http://eforward1.enom.com): connection refused

“[mzpat@charter.net](mailto:mzpat@charter.net)” is the person trying to send to me; “[musicat@doorbell.net](mailto:musicat@doorbell.net)” is the intended recipient, my domain hosted on a local ISP’s server. “[enom.com](http://enom.com)” is the domain name registrar. All mail coming to @doorbell.net is supposed to be funnelled to [musicat@doorpi.net](mailto:musicat@doorpi.net). “[doorpi.net](http://doorpi.net)” is the ISP.

What’s going on here? Is the registrar at fault, the ISP or something else? They all say things are working perfectly, but obviously they aren’t.

---

<div class="post-metadata">

**Author:** ![Musicat](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/musicat/32/20189_2.png) [@Musicat](https://boards.straightdope.com/u/Musicat)\
**Post date:** [September 4, 2003, 2:32am UTC](https://boards.straightdope.com/t/sobig-aftereffects-email-piling-up/199355/8 "2003-09-04T02:32:16Z")

</div>

**AskNott** , does your ISP let you control the settings on the spam filter, or are you at their mercy? The postini filter on mine can be tweaked by the end-user or disabled. Did you try going to your ISP’s home page?

---

<div class="post-metadata">

**Author:** ![Eurograff](https://avatars.discourse-cdn.com/v4/letter/e/df705f/32.png) [@Eurograff](https://boards.straightdope.com/u/Eurograff)\
**Post date:** [September 4, 2003, 2:52am UTC](https://boards.straightdope.com/t/sobig-aftereffects-email-piling-up/199355/9 "2003-09-04T02:52:20Z")

</div>

Well, email servers are overloaded because of Sobig.F, that’s for sure. Probably the main cause.

Anyway, there was [an article on Slashdot](http://yro.slashdot.org/article.pl?sid=03/08/25/0024204&mode=thread&tid=111&tid=126&tid=95) about shutdown of a major spammer last week. Maybe this has also had certain effect?

---

<div class="post-metadata">

**Author:** ![Bearflag70](https://avatars.discourse-cdn.com/v4/letter/b/8e7dd6/32.png) [@Bearflag70](https://boards.straightdope.com/u/Bearflag70)\
**Post date:** [September 5, 2003, 1:55am UTC](https://boards.straightdope.com/t/sobig-aftereffects-email-piling-up/199355/10 "2003-09-05T01:55:08Z")

</div>

I’ve been getting emails in my inbox that say “undeliverable” (as if I sent them and they bounced back) and they indicate I’ve got this virus. However, I have run updated Norton Antivirus, the Symantec sobic tool, and Spybot. They all say I have no virus.

Are the bounceback emails really coming from my system or from somewhere else? I think I’ll unplug my modem for a while and see if I still get these “bouncebacks”. I don’t get it.

---

<div class="post-metadata">

**Author:** ![Bearflag70](https://avatars.discourse-cdn.com/v4/letter/b/8e7dd6/32.png) [@Bearflag70](https://boards.straightdope.com/u/Bearflag70)\
**Post date:** [September 5, 2003, 2:02am UTC](https://boards.straightdope.com/t/sobig-aftereffects-email-piling-up/199355/11 "2003-09-05T02:02:10Z")

</div>

Oh, and I have also tried the manual removal instructions, but I didn’t have the particular problems in regedit that this virus purportedly creates.

---

<div class="post-metadata">

**Author:** ![Early\_Out](https://avatars.discourse-cdn.com/v4/letter/e/6f9a4e/32.png) [@Early\_Out](https://boards.straightdope.com/u/Early_Out)\
**Post date:** [September 5, 2003, 2:51am UTC](https://boards.straightdope.com/t/sobig-aftereffects-email-piling-up/199355/12 "2003-09-05T02:51:53Z")

</div>

> [@](#):
>
> \*Originally posted by Bearflag70 \*  
> \*\*I’ve been getting emails in my inbox that say “undeliverable” (as if I sent them and they bounced back) and they indicate I’ve got this virus. However, I have run updated Norton Antivirus, the Symantec sobic tool, and Spybot. They all say I have no virus.
> 
> Are the bounceback emails really coming from my system or from somewhere else? I think I’ll unplug my modem for a while and see if I still get these “bouncebacks”. I don’t get it. \*\*

[Simplifying for clarity…] This just means that somebody who has your email address in his address book has gotten the virus. So, the virus infects your friend’s machine. It picks up email addresses from his address book, and uses them as the “from” field on the spam it sends out. A lot of the messages are undeliverable, and they get bounced back. But since YOUR address now appears as the sender, they come back to you. Nothing you can do about, but wait for the storm to subside.

---

<div class="post-metadata">

**Author:** ![Bearflag70](https://avatars.discourse-cdn.com/v4/letter/b/8e7dd6/32.png) [@Bearflag70](https://boards.straightdope.com/u/Bearflag70)\
**Post date:** [September 5, 2003, 4:11am UTC](https://boards.straightdope.com/t/sobig-aftereffects-email-piling-up/199355/13 "2003-09-05T04:11:02Z")

</div>

Thanks!

---

<div class="post-metadata">

**Author:** ![Musicat](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/musicat/32/20189_2.png) [@Musicat](https://boards.straightdope.com/u/Musicat)\
**Post date:** [September 5, 2003, 5:26am UTC](https://boards.straightdope.com/t/sobig-aftereffects-email-piling-up/199355/14 "2003-09-05T05:26:47Z")

</div>

**Bearflag70,** to complicate the issue, there are some viruses that create a message saying “undeliverable” even though they are generated by the virus.

My ISP did some stuff to my account, and new emails seem to be flowing in now at a near-normal rate. But that leaves an estimated 350 messages that haven’t reached me yet or have been routed into a black hole.

What I hate about this is the uncertainty. My ISP can’t or won’t tell me if I have data waiting or not, and how long it will take before I get it and how much there is. They just say, “Let’s sit back and see what happens for a few weeks.” What a way to run a business!

---

<div class="post-metadata">

**Author:** ![Quartz](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/quartz/32/267_2.png) [@Quartz](https://boards.straightdope.com/u/Quartz)\
**Post date:** [September 5, 2003, 6:28am UTC](https://boards.straightdope.com/t/sobig-aftereffects-email-piling-up/199355/15 "2003-09-05T06:28:00Z")

</div>

As of yesterday, I was still getting 300+ per day.

---

<div class="post-metadata">

**Author:** ![slortar](https://avatars.discourse-cdn.com/v4/letter/s/6bbea6/32.png) [@slortar](https://boards.straightdope.com/u/slortar)\
**Post date:** [September 5, 2003, 1:45pm UTC](https://boards.straightdope.com/t/sobig-aftereffects-email-piling-up/199355/16 "2003-09-05T13:45:40Z")

</div>

Same here. I hate autoresponders with a passion now.

---

<div class="post-metadata">

**Author:** ![Musicat](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/musicat/32/20189_2.png) [@Musicat](https://boards.straightdope.com/u/Musicat)\
**Post date:** [September 6, 2003, 12:27am UTC](https://boards.straightdope.com/t/sobig-aftereffects-email-piling-up/199355/17 "2003-09-06T00:27:40Z")

</div>

I may not be the only one experiencing this kind of action:

> [@](#):
>
> Lycos users have gone nearly a week with no email. The No. 4 Internet portal experienced an email service freeze on Tuesday, and it’s still down. Email went offline when the company installed new software in an attempt to improve backup systems. The company hopes to restore service over the weekend.

From [http://www.techtv.com/news/shownotes/story/0,24195,3510307,00.html](http://www.techtv.com/news/shownotes/story/0,24195,3510307,00.html)  
or  
[http://www.news.com.au/common/story\_page/0,4057,7173304%5E15306,00.html](http://www.news.com.au/common/story_page/0,4057,7173304%255E15306,00.html)  
or  
[http://silicon.com/news/500019-500001/1/5885.html](http://silicon.com/news/500019-500001/1/5885.html)

But this seems to be from an upgrade that went awry, not an excess of email traffic due to viruses.

---

<div class="post-metadata">

**Author:** ![Bearflag70](https://avatars.discourse-cdn.com/v4/letter/b/8e7dd6/32.png) [@Bearflag70](https://boards.straightdope.com/u/Bearflag70)\
**Post date:** [September 6, 2003, 7:15pm UTC](https://boards.straightdope.com/t/sobig-aftereffects-email-piling-up/199355/18 "2003-09-06T19:15:37Z")

</div>

Well, last night when I went to bed at about 10 pm, I unplugged my modem. I plugged it back in at about noon today.

I received a series of these “bounceback emails” that apparently indicate the time the offending emails were sent as well as the time the emails bounced back to me. These bouncebacks indicate that my system sent out virus-laden emails and these emails bounced back to me during the period my modem was unplugged. There is nothing in my Outbox indicating that I sent anything.

This is consistent with the idea that someone else has the virus, the emails are being sent in my name from some other computer, and, as a result, they are bouncing back to me instead of bouncing back to the infected system.

I thought I would post this to help others with similar problems.

I am considering sending out a broadcast email to EVERYONE in my address book asking them to clean their systems.

---

<div class="post-metadata">

**Author:** ![Bearflag70](https://avatars.discourse-cdn.com/v4/letter/b/8e7dd6/32.png) [@Bearflag70](https://boards.straightdope.com/u/Bearflag70)\
**Post date:** [September 6, 2003, 7:21pm UTC](https://boards.straightdope.com/t/sobig-aftereffects-email-piling-up/199355/19 "2003-09-06T19:21:53Z")

</div>

Another indicator that the offending emails are not originating from my system is that the emails are bouncing back from people who are not in my address book.

---

<div class="post-metadata">

**Author:** ![Violet](https://avatars.discourse-cdn.com/v4/letter/v/ebca7d/32.png) [@Violet](https://boards.straightdope.com/u/Violet)\
**Post date:** [September 6, 2003, 7:28pm UTC](https://boards.straightdope.com/t/sobig-aftereffects-email-piling-up/199355/20 "2003-09-06T19:28:27Z")

</div>

Have not noticed any traffic jam. I get email from thousands of miles away, across continents, and they are recent.

[Next page](https://boards.straightdope.com/t/sobig-aftereffects-email-piling-up/199355.md?page=2)
